Vulnerability Intelligence Report
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
CVE-2026-58231
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94: Improper Control of Generation of Code
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP_SE | SAP Commerce Cloud (Data Hub Adapter) | COM_CLOUD 2211 (affected), 2211-JDK21 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2026-06-29T19:34:28 |
| Published | 2026-08-11T10:21:29 |
| Last Updated | 2026-08-12T03:59:57 |
Community Chatter & Buzz